Title :
Domain-Based Access Control for Collaborative E- Commerce System
Author :
Zhao, Hui ; Fang, Zhiyi ; Shi, Lijun ; Zhao, Dan
Author_Institution :
Jilin Univ., Changchun
Abstract :
The collaborative e-commerce systems are widely used between the enterprise and enterprise to strengthen cooperating ability of enterprises in dynamic business environment. Since the collaborative e-commerce systems are often shared by different enterprises, powerful access control is needed to allow different access rights to different records of the same table. Traditional access control models that define a permission as the right of a user/role to perform a specific operation on a specific object cannot handle the enormous amount of objects and user/roles. In this paper we propose an enhancement to role-based access control by introducing the domains that flexibly partition access control scope and exceed the limit of the organization frame. And, the domains fix the restrictions that can be added to the traditional concept of permissions in order to keep the number of permissions small. Furthermore, we present an implementation of our access control model at the application programming level. Although access control is performed for every single database access, our solution separates access control from the application logic by using component-based programming. With this, access control can be integrated into a four-tier information system without compiling the application programs.
Keywords :
authorisation; electronic commerce; groupware; object-oriented programming; relational databases; collaborative e-commerce system; component-based programming; database access; database table records; domain-based access control; dynamic business environment; four-tier information system; role-based access control; Access control; Authorization; Business; Collaboration; Collaborative work; Electronic commerce; Logic programming; Permission; Power system modeling; Resource management; Access Control; Domain; Integration; Restriction; Transaction;
Conference_Titel :
Pervasive Computing and Applications, 2007. ICPCA 2007. 2nd International Conference on
Conference_Location :
Birmingham
Print_ISBN :
978-1-4244-0971-6
Electronic_ISBN :
978-1-4244-0971-6
DOI :
10.1109/ICPCA.2007.4365432